PKIoverheid: TSP CIBG Findings in 2025 ETSI Audit - Incident Report #5 – Risk Management
This case is an incident report from PKIoverheid (CA owner CCADB unique ID A000068) regarding Risk Management findings from a 2025 ETSI audit. The incident disclosure source is stated as a finding by the CAB during the annual ETSI audit. The report describes several compliance issues in the Risk Management process, including that the Risk Treatment plan lacked formal approval and that risk treatment measures and their implementation status were not clearly identified. It also states deficiencies in the Risk Assessment, including that not all components, TSP processes, standards, and technical sources of risk were included, and that the supply chain risk assessment was not complete and did not include risks due to open non-conformities. The report further notes that the risk assessment file name only contained a version number. PKIoverheid states that remediation was implemented by improving the Risk Management process with additional approved deliverables, expanding the formal document management process to include risk management deliverables, and scheduling quarterly risk assessment QA review and approval; it also states that all action items were closed and requested closure of the incident report. The bug is marked RESOLVED with resolution FIXED.
- An auditor identified a Risk Management non-conformity finding during the annual ETSI audit.
- A Corrective Action Plan was created for the Risk Management incident.
- The Corrective Action Plan was approved by the auditor.
- PKIoverheid posted a Report Closure Summary stating remediation and completion of action items.
- The bug was updated to RESOLVED (FIXED).
- Logius representative — Opened a preliminary incident report describing a minor non-conformity in Risk Management and noting disclosure via the annual ETSI audit.
- Logius representative — Stated the full incident report was in final review and would be posted shortly.
- Logius representative — Posted the full incident report detailing Risk Management deficiencies, root causes, and action items with due dates and statuses.
- Logius representative — Reported that all action items have been closed and that a Report Closure Summary would be posted shortly.
- Logius representative — Posted the Report Closure Summary, describing remediation (additional approved deliverables, expanded document management, quarterly review/approval) and requesting closure after completion of action items.
- CCADB representative — Issued a final call for comments and stated the incident report would be closed on approximately 2026-02-06 if no comments were received.